MAL-2026-12199

    Dashboard / Malicious Package / MAL-2026-12199

    MAL-2026-12199

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in simple-date-formatter-new-8 (npm)

    Details: Source: amazon-inspector (4f0bf9e4040cf2940b0ca9a9e5cea7def2c660925afd0ba959ed69d28ca007b7) The package.json postinstall script runs unconditionally on `npm install`, collecting host and internal-network reconnaissance (kernel version via `uname -r`, `/etc/resolv.conf`, `hostname -I`, `/proc/net/route`, internal TCP endpoint probes, and Kubernetes API probes against 10.45.196.x /version and /api/v1/namespaces) and POSTs the aggregated output via `curl` to an attacker-controlled interact.sh OAST collector at http://safjhdvsfwzhieemkdzbgr54r0yjhrmok.oast.fun/escinfoF. A sibling postinstall.js enumerates the installer's `~/.ssh` directory and POSTs the contents along with username and platform to a hardcoded remote host at 124.221.154.135:443/post. The declared purpose is a trivial date formatter, which has no legitimate need to read SSH material, enumerate internal networks, or contact OAST infrastructure.

    Affected packages

    Package

    Name: simple-date-formatter-new-8

    Purl: pkg:npm/simple-date-formatter-new-8

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-12199 | CVE-DB